Junglewise Threat Intelligence

CVE-2026-56243: Capgo security control bypass in PostgREST/RLS plane

CVE-2026-56243 · Severity: high · CVSS 8.1 · Published 2026-06-23

Technologies: Capgo. Vendors: Capgo.

Executive brief

Capgo, a platform for managing app updates and backend services, contains a security flaw that allows users to bypass a key security setting. Even when an organization requires the use of more secure 'hashed' API keys, the system still incorrectly accepts older, less secure plaintext keys through a specific technical interface. This means that if an administrator believes they have disabled old keys to protect their data, those keys could still be used by an attacker to access sensitive organization resources and information.

Technical details

A security control bypass exists in Capgo versions prior to 12.128.2 due to an authentication policy split between the backend API and the PostgREST/Row Level Security (RLS) plane. While the backend correctly enforces the 'enforce_hashed_api_keys' setting by rejecting plaintext keys, the PostgREST plane continues to authorize plaintext keys provided via the 'capgkey' header. This occurs because the 'get_identity' and 'find_apikey_by_value' functions in the database migrations trust plaintext values even when organizational policy mandates hashed-only authentication. An attacker with an existing plaintext API key can bypass organizational security mandates to access RLS-protected tables and resources. The issue is resolved in version 12.128.2 by unifying the enforcement logic across both planes.

Affected products

  • Capgo Capgo < 12.128.2

Timeline

  • 2026-05-07: advisory: GitHub Security Advisory published
  • 2026-06-23: disclosed: CVE published to NVD

References

Related threats